Chinese Military Researchers Use US AI Models for Defence Systems

    Chinese military researchers have used outputs from leading US artificial intelligence models to train domestic AI systems, advancing China's defence capabilities.

    3 min read5 min listen

    Chinese military researchers have used outputs from leading US artificial intelligence (AI) models, developed by OpenAI and Anthropic, to train domestic AI systems. This practice aims to advance China's defence capabilities, according to a Reuters review of over 80 Chinese academic papers and patents.

    These previously unreported findings offer a rare glimpse into how military and security-linked institutions in China are leveraging cutting-edge US AI models. They use these models as a shortcut to developing specialised systems of their own. This occurs despite Washington's efforts to restrict Beijing's access to advanced chips and other strategic technologies.

    This situation fits into a broader narrative of technological competition between the United States and China. Both nations are vying for global leadership in critical technologies like AI. The use of US AI models by Chinese military entities highlights the challenges of enforcing technology export controls in a globally interconnected research environment.

    Sunny Cheung, a fellow at the Washington-based Jamestown Foundation, analysed over 60 of these papers. He stated that Chinese military scientists are systematically capturing the reasoning steps of Western models. They adapt these for surveillance, cyber warfare, and tactical decision-making. Cheung explained that teaching a model the right answer is one thing, but teaching it the reasoning behind the answer is much harder. These papers show Chinese military-linked researchers are trying to transfer that expensive, proprietary reasoning from Western models into smaller, controllable systems.

    The implications of this practice are significant for international relations and technological security. It raises questions about intellectual property rights and the effectiveness of current export controls. This issue has emerged as a major flashpoint ahead of US-China talks on AI governance and safety. Decision-makers in both countries will need to address how to manage the dual-use nature of AI technology. They must also consider the potential for military applications.

    The documents show widespread use of a technique known as "model distillation." In this process, outputs from a powerful AI system are used to train smaller, specialised models. These smaller models can then be deployed locally without the enormous computing requirements needed to build frontier AI systems from scratch. This method allows Chinese institutions to bypass some of the hardware restrictions imposed by the US.

    Reuters' review, which included data compiled by the Jamestown Foundation, showed distillation is widely used by researchers linked to the People's Liberation Army (PLA) and other military institutions. The papers suggest Chinese defence institutions see leading US AI models as both a source of technical insight and a way to close the gap with American rivals. This strategy allows them to accelerate their own AI development.

    One paper, published last year by researchers in PLA Unit 96941, described using OpenAI's GPT-3.5. This unit is a military intelligence and cyber-warfare unit in Beijing. They used GPT-3.5 to process sensitive military source code. The researchers noted that third-party models were unsuitable for handling classified information. To overcome this, they used GPT-3.5 to summarise software code. They then trained a domestic model on those summaries to run entirely within Chinese military networks.

    Chinese researchers have used distillation for various purposes, from content monitoring to military deployment. At the North University of China, which has close links to the country's weapons industry, researchers used Anthropic's Claude 3 Haiku. They used it to generate synthetic training data for a text classification model for social media monitoring and content moderation. Anthropic stated it does not provide commercial access to Claude in China or to Beijing-controlled firms. It also uses monitoring systems to detect policy violations. The company added that distilled models may lose the original systems' safety safeguards, potentially allowing sensitive capabilities to be transferred to models beyond its control.

    A 2024 paper from the PLA's National University of Defense Technology described using distillation to shrink an image-processing model. This was for deployment on unmanned aerial vehicles (UAVs). This allows drones to analyse live video and support navigation and targeting decisions in real time, even when communications are cut. Similarly, researchers at China's Academy of Military Sciences used distillation to run a target-recognition model on tactical hardware during simulated maritime operations. This broad application demonstrates the strategic importance China places on AI in its military modernization efforts.

    Comments

    More from StatsGH